Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-88m9-g755-gjf2

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Pentaho BI Server 1.7.0.1062 and earlier does not set the autocomplete tag to off on web pages using a password field, which might allow physically proximate attackers to obtain the password.

Pentaho BI Server 1.7.0.1062 and earlier does not set the autocomplete tag to off on web pages using a password field, which might allow physically proximate attackers to obtain the password.

EPSS

Процентиль: 24%
0.00083
Низкий

Дефекты

CWE-200

Связанные уязвимости

nvd
больше 14 лет назад

Pentaho BI Server 1.7.0.1062 and earlier does not set the autocomplete tag to off on web pages using a password field, which might allow physically proximate attackers to obtain the password.

EPSS

Процентиль: 24%
0.00083
Низкий

Дефекты

CWE-200